Re: [Fwd: [Asrg] Re: Documents for LMAP BOF]

Hadmut Danisch <[email protected]> Sun, 8 Feb 2004 09:16:45 +0100
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
On Sat, Feb 07, 2004 at 09:00:19PM -0500, Yakov Shafranovich wrote:
> 
> ...due to concerns from some
> ISPs that want to do one lookup per domain, slurp up all the IPs for
> that domain, and cache it, and other ISPs who want to do a simple DNSBL
> style lookup for each message.


I wonder whether it should be side product of this group to 
produce a statement of wishes/requirements for future directory
services. DNS needs to be improved or replaced anyway, and 
whois databases are a hell of different formats and missing
information.

We need a better directory service to get rid of DNS's limitations
and flaws. We have to raise the wish.

Another problem is the next step. When you received spam or fraudulous 
messages from a domain verified with LMAP, what next? E.g. german 
law requires providers of "teleservices" to provide an impressum. 

The next step after LMAP is determining who is reponsible for the 
given domain. After all, what's the use of LMAP if the domain 
is anonymous and the owner just sent a fedex envelope with cash
in order to get it? Or if the owner sits in a country where you 
can't hold him liable? Whois is far from being the solution here.

So it should be possible to quickly fetch the information about
which country/ies the domain is hosted in and who is the 
responsible administrator. If a domain does not want to reveal 
such information, it could be up to other people's choice whether
to accept mails from such a domain.

RMX/LMAP/... as we currently know it is only the first half of the 
mechanism. It will help at the moment, but spammer's will adapt.
We'll need the second part soon.

regards
Hadmut